Secure Realms during boot using Arm Confidential Compute Architecture (CCA) BootSync
Introduction
Understand Arm CCA BootSync and the Boot Injection protocol
Configure UEFI Secure Boot and disk encryption in Arm CCA Realms
Next Steps
Secure Realms during boot using Arm Confidential Compute Architecture (CCA) BootSync
Who is this for?
This Learning Path is for developers who want to understand how Arm CCA BootSync supports early Realm boot workflows such as UEFI Secure Boot and encrypted disk boot.
What will you learn?
Upon completion of this Learning Path, you will be able to:
- Understand why BootSync is needed before the Realm guest operating system has networking.
- Understand how the Boot Injection Protocol uses key exchange, attestation, and Boot Information Blocks to support the BootSync workflow.
- Use BootSync to inject UEFI variables and secret data into an Arm CCA Realm.
- Launch Arm CCA Realms with UEFI Secure Boot and an encrypted root file system on an Armv9-A AEM Base Fixed Virtual Platform (FVP) with Realm Management Extension (RME) support.
Prerequisites
Before starting, you will need the following:
- A cloud-based instance or an AArch64 or x86_64 computer running Linux. For more information about using cloud-based instances, see the Arm cloud service providers Learning Path.
- Completion of the Run an application in a Realm using the Arm Confidential Compute Architecture (CCA) Learning Path
Summary
This summary was drafted with an approved AI-assisted workflow and reviewed by Arm contributors before publication. Human technical review remains part of the process so the final page reflects engineering rigor, accuracy, and Arm editorial standards.
Frequently asked questions
These FAQs were drafted with an approved AI-assisted workflow and reviewed by Arm contributors before publication. Human technical review remains part of the process so the final page reflects engineering rigor, accuracy, and Arm editorial standards.
BIB Variable Data Requested and the expected <RPV>_VAR.dat file name. If the file is missing, BootSync reports BootSyncNotDone, and the Realm boots without Secure Boot enabled.1. Check that value to confirm the state.LUKS partition unlocked, switching root. Run df -h and verify that /dev/mapper/cryptroot is mounted at /.